GHSA-rm3q-qfrm-frrv

Suggest an improvement
Source
https://github.com/advisories/GHSA-rm3q-qfrm-frrv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rm3q-qfrm-frrv/GHSA-rm3q-qfrm-frrv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-rm3q-qfrm-frrv
Aliases
Published
2022-05-17T00:17:47Z
Modified
2024-04-24T22:43:39.556015Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
TeamPass arbitrary file upload vulnerability
Details

An arbitrary file upload vulnerability, present in TeamPass before 2.1.27.9, allows remote authenticated users to upload arbitrary files leading to Remote Command Execution. To exploit this vulnerability, an authenticated attacker has to tamper with parameters of a request to upload.files.php, in order to select the correct branch and be able to upload any arbitrary file. From there, it can simply access the file to execute code on the server.

Database specific
{
    "nvd_published_at": "2017-11-27T19:29:00Z",
    "cwe_ids": [
        "CWE-434"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2024-04-24T22:28:21Z"
}
References

Affected packages

Packagist / nilsteampassnet/teampass

Package

Name
nilsteampassnet/teampass
Purl
pkg:composer/nilsteampassnet/teampass

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.27.9

Affected versions

2.*

2.1.21
2.1.26
2.1.27